Threat reportMalwareTL-2026-3097

BPFDoor Linux backdoor (Red Menshen / Earth Bluecrow) targeting telecom infrastructure and network edge devices

highACTIVE

BPFDoor Linux backdoor (Red Menshen / Earth Bluecrow) (TL-2026-3097), also tracked as BPFdoor, is a high-severity malware campaign, first published 2026-10-09. It is attributed to Red Menshen (China) with medium confidence, affects Various Linux servers and network edge appliances (mail security, maps to 15 MITRE ATT&CK techniques (T1014, T1036.004, T1036.005), and is covered by 9 detection rules and 25 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
15MITRE ATT&CK
Actors
1Red Menshen
Detection rules
9SPL · KQL · Sigma
IOCs
25Indicators of compromise

Key facts for TL-2026-3097

Threat ID
TL-2026-3097
Also known as
BPFdoor, Backdoor.Linux.BPFDOOR, icmpShell, httpShell
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Red Menshen
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
telecoms, finance, retail, technology
Target regions
south korea, taiwan, hong kong, myanmar, malaysia, egypt, Middle East, Asia
Detection rules
9
Indicators of compromise
25

Malware and tooling in BPFDoor Linux backdoor (Red Menshen / Earth Bluecrow)

Malware and tooling: AVERAT, BPFDoor, BPFDoor - S1161, HTTP-Shell, Rapid7, rapid7_bpfdoor_check.sh

How BPFDoor Linux backdoor (Red Menshen / Earth Bluecrow) works

BPFDoor is a stealthy Linux backdoor that uses Berkeley Packet Filters to stay dormant until a magic packet arrives, with no constant beacons or listening ports. It is used against telecom providers and edge systems such as mail security gateways, VPN appliances and firewalls, and newer variants masquerade as regional software such as Korean anti-spam products and HPE ProLiant agents.

BPFDoor attaches a Berkeley Packet Filter to a raw AF_PACKET socket so the kernel inspects traffic and the implant activates only when a crafted 'magic' packet (TCP, UDP or ICMP) is seen. Because the socket is passive, there is no listening port, no periodic beacon, and the sniffing is not visible to netstat or ss; the magic packet can bypass host firewall filtering. Per Rapid7's Christiaan Beek (Help Net Security, 2026-10-09), operators keep changing how the trigger is hidden: once defenders learn to spot one activation method, the operators move to another. The malware targets appliances that cannot run EDR agents, including mail security gateways, VPN appliances, firewalls and telecom network edge systems, and in telecom networks it provides access to subscriber data, signaling flows, authentication exchanges and communications metadata for long-term collection.

Rapid7 Labs' whitepaper (published 2026-04-02, updated 2026-09-23, roughly 300 samples analysed) documents seven new variants, F through L. Variant F uses a 26-instruction BPF filter, runs from /var/run/user/0, wipes file descriptors and uses new magic bytes (0x3182, 0x2048, 0x1051, 0x1155, 0x3321, 0x5433). Variant G sniffs TCP/UDP/ICMP in multiple threads and spoofs the HPE process name hpasmlited. Variant H beacons actively with a DNS heartbeat and NTP/SSL-themed domains, and masquerades as HPE ProLiant software (cmathreshd with flags '-p 5 -s OK', lock file /var/run/cma.lock). Variant I uses an 11-instruction filter on TCP port 9999 with magic 0xA9F205C3. Variants J, K and L add an ICMP relay (and, for J and K, HTTP tunneling plus the icmpShell/httpShell families). The v2 magic packet carries a 'Hidden IP' field; a value of -1 (255.255.255.255) makes the implant open a reverse shell to the packet's source, so no hardcoded C2 address is needed. In ICMP relay mode the infected host forwards traffic to an internal target taken from that field. icmpShell uses a hardcoded ICMP sequence number 1234, RC4 key 'icmp' and an invalid ICMP code 1 heartbeat. Anti-forensics include timestomping, HISTFILE=/dev/null, stack strings, and unsetenv('LD_PRELOAD') to defeat user-mode hooks.

Trend Micro's controller analysis of BPFDoor (Earth Bluecrow) describes TCP (0x5293), UDP and ICMP (0x7255) activation modes, an MD5-with-fixed-salt password check, reverse-shell and direct-connection modes (iptables REDIRECT into ports 42391-43390, response marker '3458'), and disabling of command logging (HISTFILE and MYSQL_HISTFILE set to /dev/null). Trend lists victims in South Korea, Myanmar and Hong Kong (telecom), Malaysia (retail) and Egypt (finance) during 2024. The Hacker News (October 2026) reports BPFDoor builds against South Korean systems that impersonate the PID file of SpamSniper, a Korean anti-spam product, and rotate through ten Linux daemon names, alongside a related BPF Rekoobe build and the AVERAT implant against ShareTech appliances (dropper ntpdate, payload udevds, C2 over TCP 25 with a 600-699 second beacon).

Attribution: the Help Net Security source gives none. Other public reporting (PwC, Trend Micro, Rapid7) ties BPFDoor to the China-linked group Red Menshen (aka Earth Bluecrow, DecisiveArchitect, Red Dev 18), active against telecoms in Asia and the Middle East since 2021. Attribution confidence is rated MEDIUM here because it relies on secondary vendor reporting. No CVE is cited for BPFDoor itself; Trend lists exploitation of public-facing applications as the initial compromise path. Severity HIGH is an analyst assessment.

MITRE ATT&CK techniques used in TL-2026-3097

Defense Evasion

T1014 Rootkit; T1036.004 Masquerade Task or Service; T1036.005 Match Legitimate Resource Name or Location; T1070.003 Clear Command History; T1070.006 Timestomp; T1205.002 Socket Filters

Execution

T1059.004 Unix Shell

Command and Control

T1071.003 Mail Protocols; T1071.004 DNS; T1090.001 Internal Proxy; T1095 Non-Application Layer Protocol; T1572 Protocol Tunneling; T1573.001 Symmetric Cryptography

Initial Access

T1190 Exploit Public-Facing Application

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in BPFDoor Linux backdoor (Red Menshen / Earth Bluecrow)

  • Various — Linux servers and network edge appliances (mail security gateways, VPN appliances, firewalls, telecom edge systems)
    Vulnerable versions: Linux hosts without kernel-level packet-socket monitoring
  • HPE — ProLiant management agents (masqueraded by variants G and H)
  • ShareTech — ShareTech appliances (AVERAT dropper in /addpkg/sbin/)

Remediation for BPFDoor Linux backdoor (Red Menshen / Earth Bluecrow)

Patches

  • Keep edge appliance firmware and public-facing services current; no BPFDoor-specific CVE is cited in the sources

Immediate actions

  • Hunt Linux hosts for processes whose executable shows '(deleted)' in /proc and for root-owned processes with spoofed daemon names (hpasmlited, cmathreshd, dockerd, zabbix_agentd, qmgr)
  • Enumerate raw AF_PACKET sockets and attached BPF filters on systems that are not meant to capture traffic (Rapid7 rapid7_bpfdoor_check.sh)
  • Alert on outbound TCP port 25 from non-mail services and on ICMP echo with sequence 1234 or invalid ICMP code 1
  • Restrict management-plane access to edge appliances to dedicated admin networks

Workarounds

  • Block or filter unsolicited TCP/UDP/ICMP packets to edge hosts at upstream firewalls, since the magic packet is only seen by the host kernel BPF filter

Longer-term hardening

  • Add network-level telemetry in front of appliances that cannot host EDR agents
  • Audit auditd/eBPF telemetry for socket(AF_PACKET) and setsockopt(SO_ATTACH_FILTER) from non-capture binaries
  • Review telecom core and edge segmentation so a compromised edge host cannot reach signaling and subscriber systems

Timeline of BPFDoor Linux backdoor (Red Menshen / Earth Bluecrow)

  • Red Menshen (Earth Bluecrow) begins BPFDoor activity against telecom providers in the Middle East and Asia (year precision per public reporting).
  • PwC publicly reports BPFDoor and attributes it to Red Menshen targeting telecoms (year precision).
  • Trend Micro lists a Hong Kong telecom victim in January 2024 (month precision).
  • Trend Micro lists an Egyptian financial services victim in September 2024 (month precision).
  • Trend Micro lists telecom victims in South Korea and Myanmar in December 2024 (month precision).
  • Rapid7 Labs publishes whitepaper on seven new BPFDoor variants (F-L) from about 300 analysed samples, including httpShell and icmpShell.
  • Rapid7 updates its BPFDoor variants publication.
  • Help Net Security publishes Rapid7's Christiaan Beek on BPFDoor and network-edge attacks, noting new variants masquerading as Korean anti-spam software.

Sources cited for BPFDoor Linux backdoor (Red Menshen / Earth Bluecrow)

Detection coverage for TL-2026-3097

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3097 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
25 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats